What a SOC 2 Readiness Assessment Is
A readiness assessment measures your controls against every Trust Services Criterion in scope and tells you, control by control, what is met, partially met or missing — before an auditor is engaged. It produces a findings register, an evidence plan for the observation window, and a remediation roadmap with effort and cost attached to every gap.
It is preparation work, not attestation. Nothing it produces is a report a customer can rely on. What it does is make sure the report you eventually get is a clean one.
Why It Comes First
Because a Type 2 audits the period, not the day. This is the thing that catches companies out, and it is structural rather than fixable. The auditor draws samples across the entire observation window. A control implemented in month three produces exceptions for months one and two, and there is no version of tidying up afterwards that changes what happened.
Every week you spend in an observation window with controls that are not genuinely operating is a week of evidence working against you.
Three other things readiness catches early:
Scope that grew by default. Companies routinely scope in criteria nobody asked for, which means more controls, more evidence and a longer audit for no commercial benefit. If the trigger was one customer, we start by asking what that customer actually required.
A system description nobody owns. Section III of the report describes your system and boundaries, and it is where a procurement team checks the report covers the product they are buying. No tool writes it.
Remediation that needs engineering time. Finding out you need MFA everywhere is fast. Implementing it competes with your roadmap, and that is a conversation worth having in week two rather than month five.
What You Get
A findings register. Every control in scope scored met, partially met or not met, with the evidence we saw and the specific reason for anything short of met.
An evidence plan for the window. Which artifact proves which control, who produces it, and on what cadence — so quarterly controls actually run four times rather than once in the final quarter.
A costed remediation roadmap. Each gap with an owner, an effort estimate and a cost, sequenced so the controls the opinion depends on close first.
A scope recommendation. Whether the criteria currently in scope are the ones your customer asked for, and what dropping or adding one would cost.
A realistic date. When the window can start, and therefore when a report can actually exist. Usually the answer someone senior is waiting for.
Readiness vs the Audit
| Readiness assessment | SOC 2 audit | |
|---|---|---|
| Performed by | Consultancy (Avantcert) | Independent licensed CPA firm |
| Produces | Findings, evidence plan, roadmap | The SOC 2 report |
| Customer can rely on it | No | Yes |
| When | Before the observation window | After it closes |
| Same firm can do both | No — independence is required | No |
That last row is a requirement of the attestation standard, not a preference. A firm that builds your controls cannot form an independent opinion on them. See what actually happens in a SOC 2 audit.
How Long It Takes
| Stage | Duration | What drives it |
|---|---|---|
| Readiness assessment | 2–4 weeks | Criteria in scope, evidence turnaround |
| Remediation | 1–3 months | Engineering capacity |
| Observation window | 3–12 months | Your choice; 3 is the common first |
| Fieldwork + report | 4–10 weeks | CPA firm availability |
The assessment is the short part. Its value is that it makes the long parts predictable.
Cost
Readiness is stage one of a SOC 2 engagement and is priced within it. Avantcert engagement ranges, already discounted 30–50% below typical market rates:
| Tier | Employees | Full engagement | CPA audit fee | Max duration |
|---|---|---|---|---|
| Startup | 5–50 | from $7,000 | Separate | 90 days |
| Mid-Market | 51–200 | around $16,000 | Separate | 90 days |
| Large Enterprise | 201–500 | up to $25,000 | Separate | 90 days |
Full breakdown in the SOC 2 certification cost guide.
Book a Readiness Assessment
Tell us which criteria are in scope and your headcount. Scoped proposal within 24 hours.
Our form could not load. Email your scope and headcount and you'll get the same proposal within 24 hours.
Email your requirements Open the full quote formReadiness Assessment FAQs
What is a SOC 2 readiness assessment?
A structured assessment of your controls against every Trust Services Criterion in scope, before an auditor is engaged. It produces a findings register showing which controls are met, partially met or missing, an evidence plan for the observation window, and a remediation roadmap with effort and cost per gap.
Is a readiness assessment the same as a SOC 2 audit?
No. Readiness is preparation work performed by a consultant and produces no report a customer can rely on. The audit is performed by an independent licensed CPA firm and produces the SOC 2 report. The firm that runs your readiness is not permitted to audit you, so they are always two separate engagements.
Do I need a readiness assessment before SOC 2?
It is not mandatory. It is, however, how you avoid starting an observation window with controls that are not yet operating — which is the single most common cause of exceptions in a first Type 2 report, and it cannot be fixed retroactively once the window has run.
How long does a SOC 2 readiness assessment take?
Typically two to four weeks, depending on how many criteria are in scope and how quickly your team can produce evidence. Remediation afterwards is the longer stage, usually one to three months, and it is bounded by engineering capacity rather than by paperwork.
What happens after the readiness assessment?
You remediate the gaps, then start the observation window with controls actually running, then engage a CPA firm for fieldwork. Getting the sequence right matters: a Type 2 samples across the whole window, so every week you start before you are ready is a week of evidence that will show exceptions.
Before You Book
Work through the SOC 2 compliance checklist to see what is involved, read the full SOC 2 compliance guide if you are still scoping, or what happens during the audit if you already know where you stand.
Official reference: AICPA, SOC 2.
Know the gap before the window opens
Two to four weeks, and you get a real date instead of a hope.